MIME::Tools MIME Encoded Words Vulnerability
BID:4928
Info
MIME::Tools MIME Encoded Words Vulnerability
| Bugtraq ID: | 4928 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2002 12:00AM |
| Updated: | Jun 03 2002 12:00AM |
| Credit: | Discovered by David F. Skoll <[email protected]>. |
| Vulnerable: |
Eryq MIME::Tools 5.4.11 |
| Not Vulnerable: | |
Discussion
MIME::Tools MIME Encoded Words Vulnerability
RFC 2047 defines a method of encoding words for situations where US-ASCII may not be the default character set. It has been reported that the MIME::Tools implementation of this specification is flawed. If a US-ASCII 'whitespace' character is embedded between two MIME encoded words, MIME::Tools may incorrectly interpret the space as being a part of the decoded, concatenated string. This may result in the wrong value being extracted from a message and returned to the dependent application for use.
RFC 2047 defines a method of encoding words for situations where US-ASCII may not be the default character set. It has been reported that the MIME::Tools implementation of this specification is flawed. If a US-ASCII 'whitespace' character is embedded between two MIME encoded words, MIME::Tools may incorrectly interpret the space as being a part of the decoded, concatenated string. This may result in the wrong value being extracted from a message and returned to the dependent application for use.
Exploit / POC
MIME::Tools MIME Encoded Words Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MIME::Tools MIME Encoded Words Vulnerability
Solution:
An unofficial patch has been published. This has not been tested or confirmed by SecurityFocus:
Eryq MIME::Tools 5.4.11
Solution:
An unofficial patch has been published. This has not been tested or confirmed by SecurityFocus:
Eryq MIME::Tools 5.4.11
-
David F. Skoll mime-tools-patch.txt
http://www.roaringpenguin.com/mimedefang/mime-tools-patch.txt
References
MIME::Tools MIME Encoded Words Vulnerability
References:
References: